CVE-2023-30539: Nextcloud Files Automated Tagging

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that the Nextcloud Server is upgraded to 24.0.11 or 25.0.5, the Nextcloud Enterprise Server to 21.0.9.11, 22.2.10.11, 23.0.12.6, 24.0.11 or 25.0.5, and the Nextcloud Files automated tagging app to 1.11.1, 1.12.1, 1.13.1, 1.14.2, 1.15.3 or 1.16.1. Users unable to upgrade should disable all workflow related apps. Users are advised to upgrade.

Affected products

  • Nextcloud Nextcloud Files Automated Tagging: from 1.14.0, before 1.14.2 (fixed in 1.14.2); from 1.15.0, before 1.15.3 (fixed in 1.15.3); version 1.11.0 only; version 1.12.0 only; version 1.13.0 only; version 1.16.0 only
  • Nextcloud Nextcloud Server: from 21.0.0, before 21.0.9.11 (fixed in 21.0.9.11); from 22.0.0, before 22.2.10.11 (fixed in 22.2.10.11); from 23.0.0, before 23.0.12.6 (fixed in 23.0.12.6); from 24.0.0, before 24.0.11 (fixed in 24.0.11); from 25.0.0, before 25.0.5 (fixed in 25.0.5)

Published 2023-04-17. Last modified 2026-06-17.